Tutorial 1: Security Governance and Policy

Unit 8 ยท Governance, risk, and capstone

Objectives

Governance establishes direction, accountability, oversight, and decision rights. A policy states required intent; standards define mandatory constraints; procedures describe repeatable steps; guidelines offer advice. Policies need scope, owner, exceptions, enforcement, review date, and evidence.

board / executives -> risk appetite and accountability
security policy -> standards -> procedures -> controls -> evidence

Security should be integrated with enterprise risk, procurement, architecture, privacy, continuity, and audit. A control without an owner is not an operating control. Exceptions should be time-limited, justified, approved by appropriate authority, and tracked to closure.

Exercises

  1. Turn a vague password policy into a testable standard.
  2. Assign owners for five security controls.
  3. Design an exception workflow.

Self-check

  1. How does a standard differ from a policy?
  2. Why assign control owners?
  3. What makes an exception safe?

Self-Check Quiz

1. What does governance establish?

AnswerDirection, accountability, oversight, decision rights, and alignment between security and organizational objectives.

2. Should exceptions expire?

AnswerYes. Time limits and review prevent temporary risk acceptance from becoming permanent exposure.

Homework

  1. Write a security-policy hierarchy for an enterprise.
  2. Define control ownership and evidence.
  3. Design an exception and escalation process.
Sample answerA policy states intent, a standard defines measurable requirements, and procedures explain operation. Owners produce evidence such as configuration, review, test, or log records. Exceptions document risk, compensating controls, approver, expiry, and reassessment trigger.